Forum Discussion

nwaringa's avatar
nwaringa
New Member
9 years ago

PowerBI - Key Management

I read through the September 2016 PowerBI security whitepaper (Located here, Microsoft Trust Center). Worth noting... the feedback address listed in the document bounces back all email sent to it.

 

In particular the encryption section and all information I can find online still has me scratching my head. Can you help provide some answers to the questions below:

 

  • I gather that data imported into PowerBI is sent to Azure Blob storage. I also understand Microsoft is using  random 256-bit AES keys for storage.
    • Can these keys be defined in Azure Key Vault by the customer/tenant via a Bring your Own Key or Hold your Own Key scenario?
    • Both KEK and CEK or merely CEK? Does this handle any other keys I should be aware of?
    • How about the metadata stored in the Azure SQL repository?
  • For PowerBI Mobile, Page 18 suggests “Data is cached in storage on the device, which is not directly encrypted by the application itself”
    • Does this mean that the cached data is stored in the clear on any mobile device with the application?
      • If so, can mobile functionality be limited or turned off in the PowerBI interface?

Answers on these would greatly help us out.

 

Thanks in advance,

Nick

3 Replies

  • Greg_Deckler's avatar
    Greg_Deckler
    Community Champion

    As for the last question, I am not aware of any tenant setting to disable mobile access.

  • mgajera's avatar
    mgajera
    Frequent Visitor

    Hi Nick,

     

    My company is looking to implement Power BI only if we can have BYOK facility available. Or to disable Import Option in Power BI altogether.

     

    Did you find any further information than Power Security paper. If you have are you plese able to share it?

     

    Thanks in advance

     

    Mayur

  • Anonymous's avatar
    Anonymous
    Not applicable

    Any updates on this ??